Executive brief
Google Chromium V8 Engine contains an out-of-bounds write vulnerability triggered during array deserialization. A remote attacker can exploit this via a crafted HTML page to execute arbitrary code inside the browser sandbox.
Affected products
- Google Chrome prior to 71.0.3578.80
- Google V8 Engine
Timeline
- 2018-12-19: disclosed: Initial analysis by NIST
- 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-06-08: exploited: Reported as exploited in the wild